漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions < V6.24). Affected devices do not properly enforce access restrictions to scripts that are regularly executed by the system with elevated privileges. This could allow an authenticated local attacker to escalate their privileges in the underlying system.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Siemens SINUMERIK 安全漏洞
Vulnerability Description
Siemens SINUMERIK是德国西门子(Siemens)公司的一套控制系统。适用于所有生产领域。 Siemens SINUMERIK 828D V4,SINUMERIK 828D V5,SINUMERIK 840D sl V4和SINUMERIK ONE存在安全漏洞,该漏洞源于受影响的设备无法正确地对系统以提升的权限定期执行的脚本实施访问限制。这可能允许经过身份验证的本地攻击者升级其在底层系统中的权限。
CVSS Information
N/A
Vulnerability Type
N/A